FreeBSD Bugzilla – Attachment 176817 Details for
Bug 214360
security/vuxml: Security vulnerability in rubygem-gitlab (CVE-2016-9086)
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
VuXML entry for GitLab
security_vuxml.patch (text/plain), 1.71 KB, created by
VK
on 2016-11-09 14:29:11 UTC
(
hide
)
Description:
VuXML entry for GitLab
Filename:
MIME Type:
Creator:
VK
Created:
2016-11-09 14:29:11 UTC
Size:
1.71 KB
patch
obsolete
>Index: security/vuxml/vuln.xml >=================================================================== >--- security/vuxml/vuln.xml (revision 425795) >+++ security/vuxml/vuln.xml (working copy) >@@ -58,6 +58,40 @@ > * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) > --> > <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> >+ <vuln vid="10968dfd-a687-11e6-b2d3-60a44ce6887b"> >+ <topic>gitlab -- Directory traversal via "import/export" feature</topic> >+ <affects> >+ <package> >+ <name>rubygem-gitlab</name> >+ <range><ge>8.10.0</ge><le>8.10.12</le></range> >+ <range><ge>8.11.0</ge><le>8.11.9</le></range> >+ <range><ge>8.12.0</ge><le>8.12.7</le></range> >+ <range><ge>8.13.0</ge><le>8.13.2</le></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>GitLab reports:</p> >+ <blockquote cite="https://about.gitlab.com/2016/11/02/cve-2016-9086-patches/"> >+ <p>The import/export feature did not properly check for symbolic links >+ in user-provided archives and therefore it was possible for an >+ authenticated user to retrieve the contents of any file >+ accessible to the GitLab service account. This included >+ sensitive files such as those that contain secret tokens used >+ by the GitLab service to authenticate users.</p> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <url>https://about.gitlab.com/2016/11/02/cve-2016-9086-patches/</url> >+ <cvename>CVE-2016-9086</cvename> >+ </references> >+ <dates> >+ <discovery>2016-11-02</discovery> >+ <entry>2016-11-09</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="ae9cb9b8-a203-11e6-a265-3065ec8fd3ec"> > <topic>chromium -- out-of-bounds memory access</topic> > <affects>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 214360
: 176817